A security vulnerability has been detected in JhumanJ OpnForm up to 1.9.3. Affected by this vulnerability is an unknown functionality of the file /show/submissions. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The identifier of the patch is a2af1184e53953afa8cb052f4055f288adcaa608. To fix this issue, it is recommended to deploy a patch.
History

Thu, 09 Oct 2025 16:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:jhumanj:opnform:*:*:*:*:*:*:*:*

Thu, 09 Oct 2025 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Jhumanj
Jhumanj opnform
Vendors & Products Jhumanj
Jhumanj opnform

Wed, 08 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Oct 2025 05:45:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in JhumanJ OpnForm up to 1.9.3. Affected by this vulnerability is an unknown functionality of the file /show/submissions. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The identifier of the patch is a2af1184e53953afa8cb052f4055f288adcaa608. To fix this issue, it is recommended to deploy a patch.
Title JhumanJ OpnForm submissions cross site scripting
Weaknesses CWE-79
CWE-94
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-10-08T05:32:08.513Z

Updated: 2025-10-08T17:42:52.233Z

Reserved: 2025-10-07T13:17:05.711Z

Link: CVE-2025-11435

cve-icon Vulnrichment

Updated: 2025-10-08T17:42:33.981Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-08T06:15:34.600

Modified: 2025-10-09T16:20:09.710

Link: CVE-2025-11435

cve-icon Redhat

No data.